The Ninja Senseiโs Logbook: PDPC Decisions & Undertakings in April 2022
PDPC has published this monthโs decisions and undertakings on their official website.
Two organisations were ordered to pay a financial penalty, one was handed directions, and another one had released an undertaking which the Commission received.
๐๐๐ง๐ข๐ฎ๐ฌ๐ ๐๐ง๐ ๐๐ซ๐ข๐ง๐ข๐ญ๐ฒ ๐๐ก๐ซ๐ข๐ฌ๐ญ๐ข๐๐ง ๐๐๐ง๐ญ๐ซ๐ ๐ญ๐จ ๐ฉ๐๐ฒ ๐ฐ๐ก๐จ๐ฉ๐ฉ๐ข๐ง๐ ๐๐ข๐ง๐๐ฌ
GeniusUโs database was infiltrated due to a compromised developer password. This affected the personal data of approximately 1.26 million users. For failing to protect the personal data under its control, GeniusU was ordered to pay a whopping S$35,000.
Trinity Christian Centre, on the other hand, was ordered to pay S$20,000 for also failing to protect the personal data under its control. Its database servers were infected with ransomware, which affected the personal data of 72,285 individuals housed on those servers.
๐๐ข๐ซ๐๐๐ญ๐ข๐จ๐ง๐ฌ ๐๐จ๐ซ ๐๐๐ ๐๐จ๐ง๐ฌ๐ญ๐ซ๐ฎ๐๐ญ๐ข๐จ๐ง, ๐๐ง๐๐๐ซ๐ญ๐๐ค๐ข๐ง๐ ๐๐ฒ ๐๐๐๐-๐ ๐๐๐ซ๐ฏ๐ข๐๐๐ฌ
ACL Construction suffered a data breach, but the breached data only constitutes โbusiness contact informationโ and not personal data.
This would have been enough for the matter to be closed, but the PDPC found out that the organisation failed to appoint a Data Protection Officer (DPO). The organisation was only handed directions given the nature of its business.
Jade-E Services incorrectly sent email marketing to addresses belonging to those who had already withdrawn their consent to receive such marketing emails. In the aftermath of the incident, the company submitted an undertaking which the Commission accepted.
๐๐ก๐๐ญ ๐๐๐ง ๐ฐ๐ ๐ฅ๐๐๐ซ๐ง ๐๐ซ๐จ๐ฆ ๐ญ๐ก๐๐ฌ๐ ๐๐๐ฌ๐๐ฌ?
๐ Keep your passwords strong and unique across all accounts.
๐ Regularly scan your system for vulnerabilities.
๐ Appoint a Data Protection Officer (DPO) โ mandatory for ALL organisations in Singapore.
๐ Cooperate with your DPO to develop a culture of cyber wellness.
๐ Make good cyber hygiene a must for your employees, especially those who handle personal data in your possession.
P.S. For any further questions or if you need help with your cybersecurity and data protection compliance journey, donโt hesitate to reach out to us. We are always a text/call or email away!
๐ฑ WhatsApp: +65 8750 4250
๐ง Email: ninjas@privacy.com.sg